Privacy Policy

Last updated: 2026-08-02

This Privacy Policy explains how Unravelers Technologies (FZE) ("we", "us", or "our") collects, uses, shares, and protects personal information when you use the iHRMS platform at https://ihrms.io, our applications, and associated services (collectively, the "Service").

By accessing or using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, you should stop using the Service.

1. Scope and Roles

iHRMS is an HR SaaS platform that helps organizations manage their employees and HR operations. In most cases:

This Policy applies to personal information that we handle in connection with the provision of the Service. Your organization’s own privacy notices and policies may also apply, and will normally govern how your HR data is used. Where your organization has signed a separate Data Processing Agreement with us, that agreement governs our processing of Customer Data and prevails over this Policy in the event of conflict.

2. Information We Collect

2.1 Information You or Your Organization Provide

2.2 Special Categories of Personal Data

Some fields available in iHRMS may constitute Sensitive Personal Data under UAE Federal Decree-Law No. 45 of 2021 and comparable laws elsewhere in the GCC. Specifically, the Service provides optional fields for:

These fields are optional and are populated only where your organization chooses to use them. Where they are used, your organization is responsible for establishing a valid legal basis under applicable law - which, in most GCC jurisdictions, means explicit consent or a specific statutory permission - and for informing the affected individuals. We process this data only as a Processor, on your organization's instructions, and we do not use it for any purpose of our own.

If your organization does not require this data, we recommend leaving these fields empty. Sensitive Personal Data attracts heightened obligations and, in several jurisdictions, stricter rules on cross-border transfer.

2.3 Information Collected Automatically

2.4 Information from Third Parties

2.5 Data About People Who Are Not Our Users

The Service holds personal data about individuals who never interact with it directly - for example, emergency contacts, dependants, and job applicants. Your organization is responsible for ensuring these individuals are informed as required by applicable law, and for having a lawful basis to provide their data to us.

3. How We Use Personal Information

We do not use Customer Data to train machine learning or artificial intelligence models, and we do not sell personal information.

4. Legal Bases and Responsibilities

Where we process HR data as a Processor, your organization is responsible for establishing and documenting a valid legal basis, for providing privacy notices to employees and other affected individuals, and for obtaining any consent required - particularly for Sensitive Personal Data (section 2.2) and for cross-border transfers.

Where we act as a Controller (our own customers, website visitors, billing records, and platform security logs), we rely on the performance of a contract, our legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where required.

5. How We Share Personal Information

We share personal information with the following categories of recipient:

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

6. Sub-processors

We engage the following sub-processors to provide the Service. Each is bound by contractual obligations to protect personal data:

Sub-processorPurposeData involved
Stripe Subscription billing and payment processing Billing contact details, company name, subscription and transaction records. Card details are entered directly with Stripe and are never transmitted to or stored by us.
Cloud hosting and storage providers Application hosting, database storage, file and document storage, and backups All Customer Data, including uploaded documents and résumés
Email delivery providers Transactional email - invitations, notifications, payslips, offer letters, alerts Recipient name and email address, and the contents of the message

We will make a current list of sub-processors available on request, and will give reasonable prior notice of any new sub-processor that materially affects the processing of Customer Data.

7. Support Access to Your Data

So that we can investigate faults and provide support, a small number of authorized personnel at Unravelers Technologies (FZE) can access customer environments, and can sign in to the Service in the context of a user account in order to reproduce a reported problem. This is limited to what is necessary to diagnose and resolve the issue, and every such access is recorded.

We do not access Customer Data for any other purpose without your organization's instruction, except where required by law.

8. International Transfers

The Service uses cloud infrastructure that may store or process personal information outside the country in which the individual is located, including outside the UAE, the wider GCC, and Pakistan. Where this happens, we apply appropriate safeguards, which may include contractual protections, transfer agreements with our sub-processors, encryption in transit and at rest, and restrictions on access.

Several jurisdictions in the region restrict transfers of personal data - and particularly of Sensitive Personal Data - to countries that are not recognized as providing an adequate level of protection. If your organization is subject to data localization or transfer-restriction requirements, please contact us before uploading affected data so that we can discuss the available hosting arrangements.

9. Regional Provisions

9.1 United Arab Emirates

We are established in Sharjah, United Arab Emirates. Processing of personal data in the UAE is governed by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations as issued from time to time. Where your organization is established in a UAE financial free zone, the DIFC Data Protection Law No. 5 of 2020 or the ADGM Data Protection Regulations 2021 may apply instead, and those regimes confer their own rights and remedies.

Under the UAE PDPL, data subjects have rights including access, correction, erasure, restriction of processing, objection, data portability, and the right to withdraw consent. Requests should be directed as set out in section 10.

9.2 Other GCC States

Where your organization or its employees are located elsewhere in the GCC, additional or alternative laws may apply, including the Saudi Personal Data Protection Law (Royal Decree M/19 of 2021, as amended) and its regulations administered by SDAIA; the Bahrain Personal Data Protection Law No. 30 of 2018; the Qatar Law No. 13 of 2016 on Personal Data Privacy Protection; the Oman Personal Data Protection Law (Royal Decree 6/2022); and the data protection regulations issued by CITRA in Kuwait. Several of these impose their own registration, localization, or transfer conditions. Your organization remains responsible for determining which regime applies to it and for instructing us accordingly.

9.3 Pakistan

Pakistan does not currently have a single comprehensive data protection statute in force; a Personal Data Protection Bill has been under consideration for some time. In the meantime, processing may be affected by the Prevention of Electronic Crimes Act 2016 (PECA), by constitutional privacy protections, and by sector-specific rules - including State Bank of Pakistan requirements where financial or payroll banking data is involved.

Regardless of the position under local law, we apply the same technical and organizational safeguards described in this Policy to personal data originating in Pakistan, and we handle data subject requests from Pakistan on the same basis as those from the UAE. Where Pakistani law is later amended, we will update this Policy accordingly.

10. Your Rights and Choices

Depending on applicable law, individuals may have rights to:

Employees and job applicants should contact their employer or the organization that holds their record, since that organization controls the data. The Service provides a personal data export function so that individuals can obtain a copy of their own record, and this remains available even if the organization's subscription has lapsed.

We will assist our customers in responding to such requests as required by applicable law. For data we control directly, contact us using the details in section 15. We may need to verify identity before responding.

11. Cookies and Similar Technologies

We use cookies and similar technologies that are strictly necessary to operate the Service - to keep you signed in, maintain your session, protect against cross-site request forgery, and remember interface preferences such as your dashboard layout. We do not use third-party advertising cookies.

You can adjust cookie settings in your browser, but disabling strictly necessary cookies will prevent you from signing in.

12. Data Security

We use technical and organizational measures appropriate to the risk, including encryption of data in transit, hashed storage of passwords, role-based access controls, tenant isolation so that one organization cannot access another's data, audit logging, and access restrictions on our own personnel.

No system is completely secure and we cannot guarantee absolute security. You share responsibility by keeping credentials confidential, managing user roles carefully, removing access promptly when someone leaves, and using secure networks and devices.

13. Personal Data Breaches

If we become aware of a personal data breach affecting Customer Data, we will notify the affected organization without undue delay, providing the information reasonably available to us about the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the measures taken. Where we act as Processor, notification to regulators and to affected individuals is the responsibility of your organization as Controller, and we will provide reasonable assistance.

14. Data Retention

We retain personal information for as long as necessary to provide the Service, and thereafter as required for legal, accounting, tax, or reporting obligations. Employment and payroll records are frequently subject to statutory minimum retention periods in the UAE, other GCC states, and Pakistan; your organization is responsible for setting retention that meets its own obligations.

Audit and security logs are retained to support accountability and dispute resolution, and may outlive the records they describe. On termination, we make Customer Data available for export for a limited period, after which it is deleted or anonymized in accordance with your commercial agreement, subject to any legal hold or backup retention cycle.

15. Children’s Privacy

The Service is intended for organizations and for adults in a professional context. It is not directed at children, and we do not knowingly collect personal information from children. Where your organization records data about employees' dependants, that data is provided by the employee and is processed solely for HR administration.

16. Third-Party Websites and Services

The Service may link to third-party websites or services. This Policy does not apply to them, and we encourage you to review their privacy policies.

17. Changes to This Privacy Policy

We may update this Policy to reflect changes in our practices, the Service, or applicable requirements. We will post the updated Policy and update the "Last updated" date. Where a change materially affects how we process personal data, we will provide additional notice by email or in-product message.

18. Contact Us

For questions, concerns, or requests relating to this Policy or our handling of personal information, contact us at:

Company: Unravelers Technologies (FZE)
Product: iHRMS
Website: https://unravelers.tech
Product Website: https://ihrms.io
Email: info@ihrms.io
Address: Block B, Office - B51-140 SRTIP, Sharjah, United Arab Emirates